Debian Libsdl2-Image vulnerabilities
27 known vulnerabilities affecting debian/libsdl2-image.
Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH19MEDIUM8
Vulnerabilities
Page 1 of 2
CVE-2019-5060P3HIGHCVSS 8.8fixed in libsdl2-image 2.0.5+dfsg1-1 (bookworm)2019
CVE-2019-5060 [HIGH] CVE-2019-5060: libsdl2-image - An exploitable code execution vulnerability exists in the XPM image rendering fu...
An exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow in the colorhash function, allocating too small of a buffer. This buffer can then be written out of bounds, resulting in a heap overflow, ultimately ending in code execution. An attacker can displ
debian
CVE-2019-5052P3HIGHCVSS 8.8fixed in libsdl2-image 2.0.5+dfsg1-1 (bookworm)2019
CVE-2019-5052 [HIGH] CVE-2019-5052: libsdl2-image - An exploitable integer overflow vulnerability exists when loading a PCX file in ...
An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little memory being allocated, which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.
Scope: loc
debian
CVE-2019-5057P3HIGHCVSS 8.8fixed in libsdl2-image 2.0.5+dfsg1-1 (bookworm)2019
CVE-2019-5057 [HIGH] CVE-2019-5057: libsdl2-image - An exploitable code execution vulnerability exists in the PCX image-rendering fu...
An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A specially crafted PCX image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.0.5+dfsg1-1)
bullseye: resolved (fixed i
debian
CVE-2019-5059P3HIGHCVSS 8.8fixed in libsdl2-image 2.0.5+dfsg1-1 (bookworm)2019
CVE-2019-5059 [HIGH] CVE-2019-5059: libsdl2-image - An exploitable code execution vulnerability exists in the XPM image rendering fu...
An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow, allocating too small of a buffer. This buffer can then be written out of bounds resulting in a heap overflow, ultimately ending in code execution. An attacker can display a specially crafted
debian
CVE-2019-5058P3HIGHCVSS 8.8fixed in libsdl2-image 2.0.5+dfsg1-1 (bookworm)2019
CVE-2019-5058 [HIGH] CVE-2019-5058: libsdl2-image - An exploitable code execution vulnerability exists in the XCF image rendering fu...
An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.0.5+dfsg1-1)
bullseye: resolved (fixed i
debian
CVE-2018-3977P3HIGHCVSS 8.8fixed in libsdl2-image 2.0.3+dfsg1-3 (bookworm)2018
CVE-2018-3977 [HIGH] CVE-2018-3977: libsdl2-image - An exploitable code execution vulnerability exists in the XCF image rendering fu...
An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.3. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.0.3+dfsg1-3)
bullseye: resolved (fixed i
debian
CVE-2019-5051P3HIGHCVSS 8.8fixed in libsdl2-image 2.0.5+dfsg1-1 (bookworm)2019
CVE-2019-5051 [HIGH] CVE-2019-5051: libsdl2-image - An exploitable heap-based buffer overflow vulnerability exists when loading a PC...
An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.0.5+dfsg1-1)
bullseye: resolved (
debian
CVE-2018-3839P3HIGHCVSS 8.8fixed in libsdl2-image 2.0.3+dfsg1-1 (bookworm)2018
CVE-2018-3839 [HIGH] CVE-2018-3839: libsdl2-image - An exploitable code execution vulnerability exists in the XCF image rendering fu...
An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed i
debian
CVE-2017-14441P3HIGHCVSS 8.8fixed in libsdl2-image 2.0.3+dfsg1-1 (bookworm)2017
CVE-2017-14441 [HIGH] CVE-2017-14441: libsdl2-image - An exploitable code execution vulnerability exists in the ICO image rendering fu...
An exploitable code execution vulnerability exists in the ICO image rendering functionality of SDL2_image-2.0.2. A specially crafted ICO image can cause an integer overflow, cascading to a heap overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.0.3+d
debian
CVE-2017-2887P3HIGHCVSS 8.8fixed in libsdl2-image 2.0.1+dfsg-4 (bookworm)2017
CVE-2017-2887 [HIGH] CVE-2017-2887: libsdl2-image - An exploitable buffer overflow vulnerability exists in the XCF property handling...
An exploitable buffer overflow vulnerability exists in the XCF property handling functionality of SDL_image 2.0.1. A specially crafted xcf file can cause a stack-based buffer overflow resulting in potential code execution. An attacker can provide a specially crafted XCF file to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.0.1+dfsg-4)
b
debian
CVE-2017-14440P3HIGHCVSS 8.8fixed in libsdl2-image 2.0.3+dfsg1-1 (bookworm)2017
CVE-2017-14440 [HIGH] CVE-2017-14440: libsdl2-image - An exploitable code execution vulnerability exists in the ILBM image rendering f...
An exploitable code execution vulnerability exists in the ILBM image rendering functionality of SDL2_image-2.0.2. A specially crafted ILBM image can cause a stack overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.0.3+dfsg1-1)
bullseye: resolved (fix
debian
CVE-2017-14442P3HIGHCVSS 8.8fixed in libsdl2-image 2.0.3+dfsg1-1 (bookworm)2017
CVE-2017-14442 [HIGH] CVE-2017-14442: libsdl2-image - An exploitable code execution vulnerability exists in the BMP image rendering fu...
An exploitable code execution vulnerability exists in the BMP image rendering functionality of SDL2_image-2.0.2. A specially crafted BMP image can cause a stack overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.0.3+dfsg1-1)
bullseye: resolved (fixed
debian
CVE-2017-12122P3HIGHCVSS 8.8fixed in libsdl2-image 2.0.3+dfsg1-1 (bookworm)2017
CVE-2017-12122 [HIGH] CVE-2017-12122: libsdl2-image - An exploitable code execution vulnerability exists in the ILBM image rendering f...
An exploitable code execution vulnerability exists in the ILBM image rendering functionality of SDL2_image-2.0.2. A specially crafted ILBM image can cause a heap overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.0.3+dfsg1-1)
bullseye: resolved (fixe
debian
CVE-2017-14448P3HIGHCVSS 8.8fixed in libsdl2-image 2.0.3+dfsg1-1 (bookworm)2017
CVE-2017-14448 [HIGH] CVE-2017-14448: libsdl2-image - An exploitable code execution vulnerability exists in the XCF image rendering fu...
An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.2. A specially crafted XCF image can cause a heap overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.0.3+dfsg1-1)
bullseye: resolved (fixed
debian
CVE-2017-14449P3HIGHCVSS 7.5fixed in libsdl2-image 2.0.3+dfsg1-1 (bookworm)2017
CVE-2017-14449 [HIGH] CVE-2017-14449: libsdl2-image - A double-Free vulnerability exists in the XCF image rendering functionality of S...
A double-Free vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.2. A specially crafted XCF image can cause a Double-Free situation to occur. An attacker can display a specially crafted image to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.0.3+dfsg1-1)
bullseye: resolved (fixed in 2.0.3+dfsg1-1)
forky: re
debian
CVE-2019-13616P3HIGHCVSS 8.1fixed in libsdl1.2 1.2.15+dfsg2-5 (bookworm)2019
CVE-2019-13616 [HIGH] CVE-2019-13616: libsdl1.2 - SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-b...
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c.
Scope: local
bookworm: resolved (fixed in 1.2.15+dfsg2-5)
bullseye: resolved (fixed in 1.2.15+dfsg2-5)
debian
CVE-2019-12219P3HIGHCVSS 8.8fixed in libsdl2-image 2.0.5+dfsg1-1 (bookworm)2019
CVE-2019-12219 [HIGH] CVE-2019-12219: libsdl2-image - An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 whe...
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is an invalid free error in the SDL function SDL_SetError_REAL at SDL_error.c.
Scope: local
bookworm: resolved (fixed in 2.0.5+dfsg1-1)
bullseye: resolved (fixed in 2.0.5+dfsg1-1)
forky: resolved (fixed in 2.0.5+
debian
CVE-2019-7635P3HIGHCVSS 8.1fixed in libsdl1.2 1.2.15+dfsg2-5 (bookworm)2019
CVE-2019-7635 [HIGH] CVE-2019-7635: libsdl1.2 - SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-b...
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.
Scope: local
bookworm: resolved (fixed in 1.2.15+dfsg2-5)
bullseye: resolved (fixed in 1.2.15+dfsg2-5)
debian
CVE-2018-3838P4MEDIUMCVSS 6.5fixed in libsdl2-image 2.0.3+dfsg1-1 (bookworm)2018
CVE-2018-3838 [MEDIUM] CVE-2018-3838: libsdl2-image - An exploitable information vulnerability exists in the XCF image rendering funct...
An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds read on the heap, resulting in information disclosure. An attacker can display a specially crafted image to trigger this vulnerability.
Scope: local
bookworm: resolved (f
debian
CVE-2017-14450P4HIGHCVSS 7.1fixed in libsdl2-image 2.0.3+dfsg1-1 (bookworm)2017
CVE-2017-14450 [HIGH] CVE-2017-14450: libsdl2-image - A buffer overflow vulnerability exists in the GIF image parsing functionality of...
A buffer overflow vulnerability exists in the GIF image parsing functionality of SDL2_image-2.0.2. A specially crafted GIF image can lead to a buffer overflow on a global section. An attacker can display an image to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.0.3+dfsg1-1)
bullseye: resolved (fixed in 2.0.3+dfsg1-1)
forky: resolved (
debian
1 / 2Next →